wk-pr
Warn
Audited by Snyk on Aug 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In wk-pr, Step 1 reads open PR metadata via
gh pr list --state open --json headRefName(and latergh pr list --state open --json number,files) which includes outsider-authored free text in PR metadata such as titles/filenames and comment-bearing fields that can be influenced by non-owner users.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata